rootpwn

critical · CVSS v3 9.8 · CVSS v4 7.7

CVE-2026-82928

mH-DEVELOPER smart home module contains a hardcoded SSH public key that allows root login via key authentication, enabling attackers with th

Overview

mH-DEVELOPER smart home module contains a hardcoded SSH public key that allows root login via key authentication, enabling attackers with the matching private key to gain full system compromise. The key persists across factory resets and cannot be removed without remounting the filesystem. This backdoor poses a critical risk to device security.

Description

mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes. This issue was fixed in version 3.0.30

Impact

Confidentiality, integrity, and availability are compromised as attackers can obtain root access, effectively taking control of the device. Device owners, homeowners, and any users of the affected smart home module are impacted. Defenders should treat all affected devices as compromised until patched.

Remediation

Update the firmware to version 3.0.30 or later. If an update is not possible, disable SSH root login by editing /etc/ssh/sshd_config to set PermitRootLogin no and remove the hardcoded key from /root/.ssh/authorized_keys after remounting the filesystem as read‑write. Reboot the device to apply changes and monitor logs for unauthorized SSH activity.

Risk context

The vulnerability has a critical severity with a CVSS v3 score of 9.8 and no EPSS data available, indicating a high likelihood of exploitation. Immediate action is required to prevent potential full system compromise.

Affected products

  • mH-DEVELOPER Smart Home Module

Scores

Severity
critical
CVSS v2
10
CVSS v3
9.8
CVSS v4
7.7
EPSS
—

ssh backdoor root smart-home firmware critical vulnerability

← All CVEs